๐Ÿงช Community โœ“ Claude Code โœ“ Claude Desktop Standalone โ€ข Secops-pack

Secops Pack

Security Operations โ€” cross-vendor alert triage, containment playbooks, and incident timelines across your EDR/MDR/SIEM stack.

Installation

Install this plugin individually:

/plugin marketplace add wyre-technology/msp-claude-plugins --plugin secops-pack

Or install all MSP plugins at once:

/plugin marketplace add wyre-technology/msp-claude-plugins

Features

  • Alert Severity Normalization
  • Bec Response
  • Containment Playbooks

Skills

This plugin provides 3 skills that teach Claude about Secops Pack:

Skill Description
alert-severity-normalization Use this skill when triaging security alerts, incidents, or findings that come from more than one connected EDR/MDR/SIEM vendor and a single, comparable severity ranking is needed.
bec-response Use this skill when Business Email Compromise (BEC) is suspected or confirmed for a client.
containment-playbooks Use this skill when a security incident has been confirmed or is highly suspected and immediate first-response containment steps are needed.

Agents

This plugin provides 3 agents for autonomous task execution:

Agent Description
incident-timeline-builder Use this agent when a security incident needs to be reconstructed into a single chronological timeline suitable for a client-facing incident report, pulling every relevant event across every connected security, PSA, and documentation tool for the client and time window in question.
overnight-alert-summarizer Use this agent when a technician needs a morning read on everything that fired overnight across the connected EDR/MDR/SIEM stack, normalized into one ranked digest instead of five separate vendor consoles.
tenant-exposure-ranker Use this agent when the MSP needs a portfolio-wide read on which clients carry the most current security risk โ€” open critical findings, unpatched or uncontained threats, MFA coverage gaps, and stale EDR/agent coverage โ€” ranked so leadership or the security team can prioritize attention.

Commands

Available slash commands:

Command Description
/incident-report Build a client-facing incident summary for a given client and time window, assembling a chronological timeline across every connected security, PSA, and documentation tool
/portfolio-sweep Sweep every connected security tool across all clients/tenants, normalize findings, and report the top most urgent items portfolio-wide
/tenant-exposure Run the exposure ranking for one client or the whole portfolio โ€” open critical findings, unmitigated threats, MFA gaps, and stale EDR coverage

API Reference

Base URL
Authentication
Rate Limit
Documentation

Example Usage

Build a client-facing incident summary for a given client and time window, assembling a chronological timeline across every connected security, PSA, and documentation tool

/incident-report

Sweep every connected security tool across all clients/tenants, normalize findings, and report the top most urgent items portfolio-wide

/portfolio-sweep

Run the exposure ranking for one client or the whole portfolio โ€” open critical findings, unmitigated threats, MFA gaps, and stale EDR coverage

/tenant-exposure

Using Skills

/skill secops-pack:alert-severity-normalization

Use this skill when triaging security alerts, incidents, or findings that come from more than one connected EDR/MDR/SIEM vendor and a single, comparable severity ranking is needed.